Re: Supporting sudoUser:!foo in sudo.ldap

"Michael Felt" <[email protected]> Tue, 14 Dec 2021 10:47:21 -0700
Newsgroups gmane.comp.tools.sudo.devel
Message-ID <[email protected]>
If you mean add a ! (not) operator, and that it should apply to any combination of any label now used to construct access control logic - imho, that make perfect sense. Stronger, I would think it was a bug when the others did not work.

Regards,
Michael

-----Original Message-----
From: sudo-workers <[email protected]> On Behalf Of Todd C. Miller
Sent: Tuesday, 14 December 2021 08:56
To: Simon Lees <[email protected]>
Cc: [email protected]
Subject: Re: [sudo-workers] Supporting sudoUser:!foo in sudo.ldap

I think this is worth pursuing.  The question I have is whether supporting !username is sufficient.  If we are going to support this kind of construct, it should probably mirror the existing query that contains uid, groups, gids and netgroups.

Does that make sense?

 - todd
____________________________________________________________
sudo-workers mailing list <[email protected]> For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers

____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers